Earlier quoted context omitted.
How many read-write services can you use to redirect traffic to your C2 infrastructure while almost guaranteeing organizations will allow outbound connections to it and not look too closely at it?
Google Docs/Forms/Sheets/etc, anything with an image proxy, probably Microsoft's Office Online stuff tho I personally haven't used it, webpush connections, the possibilities are endless.
Tell HN: Domain fronting to be blocked on Azure
91–100 of 132 posts
Re: Tell HN: Domain fronting to be blocked on Azure
#92Earlier quoted context omitted.
Yeah, I believe China doesn't even allow TLSv1.3
Not allowing TLS 1.3 means nothing (no modern web sites) works. Modern browsers and servers both speak TLS 1.3 and if they can't they give up. Some things don't work in China, but China wouldn't have a thriving economy if nothing was working. So no, they did not block TLS 1.3 although it's interesting how this rumour seems to have self-popularised. China blocks certain popular sites, but it does not block whole proto…
Re: Tell HN: Domain fronting to be blocked on Azure
#93Earlier quoted context omitted.
> You can't write tech that overrides the authority of governments Really? Tor springs to mind.
Same. What's your point? VPNs also bypass government blocks. It's a cat and mouse game, they block vpns and guards as they see fit when they have a good reason to. Look at tor, if a country tls decrypts everything and blocks connections that can't be decrypted can it still bypass their blocks? Just because not every government is doing it does not mean Tor can't be blocked. Hell, countries allow-list connections to a…
Re: Tell HN: Domain fronting to be blocked on Azure
#94Well, that sucks. What's worse is it is wankers in the "infosec" industry that pushed MS to do this (or at least, are taking credit for it).
Could you explain to me how "nibbleshifter" would use the "feature" for good? What are you losing here "nibbleshifter"? Why do you put infosec in scare quotes? Why are they "wankers"? Why scare quote and name call a legitimate profession? Because you have qualms?
Tor's "meek" pluggable transport uses domain fronting for this purpose.
I work in the so called "infosec" field, and about half the field are myopic wankers who would readily sacrifice privacy wholesale to gain an ounce of so called security. Think: the kind of people who also want to cripple eSNI or DoH in the name of "network monitoring".
Re: Tell HN: Domain fronting to be blocked on Azure
#95Re: Tell HN: Domain fronting to be blocked on Azure
#96Earlier quoted context omitted.
It absolutely does not work. Violence finds a way.
The mind is humanity's most lethal weapon. With the "right" mindset the entire universe can become a weapon. Efforts to reduce violence tend to focus on the presence of concrete weapons (because this is easier to quantify and measure etc) with much less focus on violent ideation and the root causes of the various forms of interpersonal violence. Reducing violence is a tricky thing because to a large extent it seems t…
Re: Tell HN: Domain fronting to be blocked on Azure
#97Earlier quoted context omitted.
How many read-write services can you use to redirect traffic to your C2 infrastructure while almost guaranteeing organizations will allow outbound connections to it and not look too closely at it?
Google Docs/Forms/Sheets/etc, anything with an image proxy, probably Microsoft's Office Online stuff tho I personally haven't used it, webpush connections, the possibilities are endless.
The other 'possibilities' are not necessarily guaranteed to be allowed for egress traffic out of an organization. That's why the cloud providers blocking it is a big deal - most orgs WILL allow outbound traffic on more than a few ports to these platforms
Re: Tell HN: Domain fronting to be blocked on Azure
#98Lack of SNI encryption is the Achilles heel of modern web when it comes to oppressive regimes blocking access. Between encrypted SNI (Or domain name fronting), encrypted DNS and of course HTTPS. The biggest legitimate use case of Tor would vanish.
Your comment was on point up until this. Just because the Tor use you seemingly most identify with is access from oppressive regimes to the western web, doesn't mean that the rest should be shunned. If you want to make political points about specific other uses of Tor, do it explicitly rather than maligning the whole project.
Re: Tell HN: Domain fronting to be blocked on Azure
#99Earlier quoted context omitted.
Domain fronting leads to collateral damage in terms of blocking. If I really want to block X and X is using domain fronting to blend in with traffic on a given CDN, that CDN is going to get blocked. CDN customers that are having their stuff blocked because of that are not going to be happy, in general.
The goal is to get people to stop wanting to block X in the first place. Alternatively, make it so they have to block the entire internet along with X.